XXL-CONF Path Traversal vulnerability
High severity
GitHub Reviewed
Published
Dec 19, 2018
to the GitHub Advisory Database
•
Updated Sep 11, 2023
Description
Published to the GitHub Advisory Database
Dec 19, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 11, 2023
An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via
../
in the keys parameter that can download any configuration file, related toConfController.java
andPropUtil.java
.References